Background
Seventeen natural persons, who were minority shareholders in a Latvian public limited liability company, challenged Latvian rules requiring the Companies Register to make shareholder-register data publicly available online. The data included shareholders’ identities and contact details, share class, number and nominal value, and voting rights. Unidentified users could access the information and download it in bulk.
The Latvian Constitutional Court asked whether EU company-law disclosure rules required publication of data on every shareholder and whether the GDPR and the Charter permitted unrestricted public access. Latvia relied on business transparency, protection of third parties, anti-money-laundering and counter-terrorist-financing objectives, and sanctions enforcement.
The Court’s Holding
The Court held that Article 14(d) of Directive 2017/1132 does not require disclosure of information about all shareholders, including minority shareholders. That provision concerns persons appointed to bodies that represent, administer, supervise or control the company. Shareholders are not appointed to or removed from office in those bodies, and the powers exercised through a general meeting are not equivalent to taking part in corporate administration, supervision or control.
The Court further held that Articles 5 and 6 GDPR, read with Articles 7 and 8 of the Charter, preclude national legislation requiring unrestricted public disclosure of the specified data for all shareholders. The online, bulk-downloadable disclosure constituted a serious interference with privacy and data-protection rights. It was neither necessary nor proportionate for protecting third parties, combating money laundering and terrorist or proliferation financing, or enforcing sanctions, particularly where access was available to anyone without a legitimate-interest requirement and without sufficient safeguards against misuse.
Key Takeaways
- EU company-law disclosure rules do not mandate publication of information about every shareholder in a public limited company.
- Minority shareholders do not ordinarily “take part” in company administration, supervision or control under Article 14(d) of Directive 2017/1132.
- Member States cannot provide unrestricted public, online and bulk-downloadable access to minority shareholders’ personal and shareholding data on the grounds advanced in this case.
Why It Matters
The judgment limits Member States’ ability to treat shareholder-register transparency as a basis for open public disclosure of personal data. It distinguishes shareholders—especially minority investors—from directors and other persons empowered to bind or manage a company.
For anti-money-laundering and sanctions objectives, the Court emphasized less intrusive alternatives, including access limited to persons able to show a legitimate interest and disclosure focused on persons subject to sanctions.